Alerts This Week
Warning Icon 1 991
Alerts This Week
Warning Icon 1 991

Ubuntu 25.10 node-tar-fs Important File Overwrite Issues CVE-2024-12905

ubuntu
Calendar Grey June 2, 2026
Dist Ubuntu Esm H88
Multiple security issues fixed in node-tar-fs for Ubuntu desktop and server impacting file extraction processes.
Several security issues were fixed in tar-fs.

Summary

Several security issues were fixed in tar-fs.

Software Description:

- node-tar-fs: File system bindings for tar-stream

Details:

It was discovered that tar-fs did not properly limit paths when

extracting crafted tar files. An attacker could possibly use this

issue to write or overwrite files outside the intended extraction

directory. This issue only affected Ubuntu 22.04 LTS and Ubuntu

24.04 LTS. (CVE-2024-12905)

It was discovered that tar-fs did not properly validate extraction

paths for certain crafted tar archives. An attacker could possibly

use this issue to write files outside the intended extraction

directory. This issue only affected Ubuntu 22.04 LTS and Ubuntu

24.04 LTS. (CVE-2025-48387)

It was discovered that tar-fs had a symlink validation bypass when

extracting crafted tar files. An attacker could possibly use this

issue to write files outside the intended extraction directory.

(CVE-2025-59343)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  node-tar-fs                     3.0.9+~cs2.0.4-1+deb13u1build0.25.10.1

Ubuntu 24.04 LTS
  node-tar-fs                     2.1.1-6ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro

Ubuntu 22.04 LTS
  node-tar-fs                     2.1.1-6ubuntu0.22.04.1~esm1
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8367-1

CVE-2024-12905, CVE-2025-48387, CVE-2025-59343

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8367-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here